managing-postman

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bash scripts to perform API requests via curl and process results with jq. All commands are restricted to the official Postman API domain.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles the POSTMAN_API_KEY through an environment variable, which is a secure practice for managing API credentials. Additionally, it includes explicit logic to detect and redact environment and collection variables marked as 'secret' before they are displayed to the user.
  • [DYNAMIC_EXECUTION]: Code is executed via bash script blocks within the skill to interact with external services. The scripts are static and focus on API interaction without dynamic code generation from untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Postman API.
  • Ingestion points: Data enters the agent context through Postman API responses (SKILL.md).
  • Boundary markers: The skill includes output rules to summarize data and limit output length, though explicit boundary delimiters are not present in the script snippets.
  • Capability inventory: The skill uses bash to execute curl and jq commands (SKILL.md).
  • Sanitization: The skill implements redaction logic for 'secret' type variables in collections and environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-postman